Database/Kernel, userspace & hypervisor
QEMU (virtio-net): Map leaking on error during receive - guest-triggered host memory exhaustion / DoS
CVSS 7.5CVE-2022-26353Kernel, userspace & hypervisorcurated
Impact
Map leaking on error during receive - guest-triggered host memory exhaustion / DoS
Who can reach it
Tenant VM guest
What to do
QEMU update + VM restart or live-migration
References
Related entries
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
- OpenSSL 3.0: X.509 email-address punycode buffer overflow (4-byte stack overflow)CVE-2022-3602 · OpenSSL 3.0High
- OpenSSL 3.0: X.509 email-address variable-length buffer overflow (DoS)CVE-2022-3786 · OpenSSL 3.0High
- AMD CPU (Sinkclose): Sinkclose: SMM lock bypassCVE-2023-31315 · AMD CPU (Sinkclose)High
- Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: A host sending an H2CData command with a DATALCVE-2023-52454 · Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.cHigh
- Linux kernel (net/tls): A receiver that holds its TCP window at zero keeps the kTLS sender blocked inside tx_lockCVE-2023-54306 · Linux kernel (net/tls)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.